CVE-2024-50378 - CVE House
Back to Database
Status published Unknown CVE-2024-50378

Apache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cli

Vulnerability Description

Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive variables were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.10.3 or a later version, which addresses this issue. Users who previously used the CLI to set secret variables should manually delete entries with those variables from the log table.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-50378

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Saurabh Banawar
  • Shubham Raj

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Airflow
Vulnerable Versions:
0

Timeline

Official Publish: November 8th, 2024
Last Modified: November 8th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)